Skip to content

fix(ci): gate releases on native artifact checks - #137

Closed
sadiksaifi wants to merge 1 commit into
mainfrom
fix/verify-macos-release-artifacts
Closed

sadiksaifi wants to merge 1 commit into
mainfrom
fix/verify-macos-release-artifacts

Conversation

@sadiksaifi

@sadiksaifi sadiksaifi commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

Description

Prevent corrupt, incorrectly targeted, invalidly signed, or non-launching binaries from reaching GitHub releases, Homebrew, or npm. The tag-only release workflow now validates the exact archives on native runners before any publication step can start.

These jobs run only for version tags in .github/workflows/release.yml; normal pull-request and branch CI remains unchanged.

What is the purpose of this pull request?

  • Bug fix
  • New Feature
  • Documentation update
  • Code refactoring
  • Performance improvement
  • Other

Changes

  • Build all six platform archives once and transfer them through GitHub Actions artifacts.
  • Verify Linux ARM64/x64 binaries on native Ubuntu runners.
  • Verify Windows ARM64/x64 PE architecture, version, and startup on native Windows runners.
  • Re-sign macOS ARM64/x64 binaries on native macOS runners, preserve Bun's entitlements/runtime flags, and strictly verify the final packaged archives.
  • Require exact native architecture and ai-git --version checks for every platform.
  • Assemble checksums only from verified archives.
  • Gate GitHub release creation, Homebrew updates, and npm publication on every native verification job.
  • Keep write permission only on the publication job; build and verification jobs remain read-only.
  • Use current major-version tags for GitHub Actions.

Testing

  • Tested on macOS version: 27.0
  • Tested with different input types
  • Tested in pipe chains
  • Ran actionlint .github/workflows/release.yml successfully.
  • Validated workflow YAML and ran git diff --check.
  • Confirmed normal CI configuration is unchanged and release verification remains tag-only.
  • Re-signed, repackaged, re-extracted, strictly verified, and executed the published v3.0.2 macOS ARM64 archive locally.
  • Independently reviewed runner labels, artifact paths, native architecture checks, job dependencies, and permissions.

Screenshots

Not applicable.

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • My changes generate no new warnings
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes

@sadiksaifi
sadiksaifi force-pushed the fix/verify-macos-release-artifacts branch from 1271fcf to 1a6228f Compare September 20, 2026 10:54
@sadiksaifi sadiksaifi changed the title fix(ci): verify macOS release artifacts fix(ci): gate releases on native artifact checks Sep 20, 2026
@sadiksaifi sadiksaifi closed this Sep 20, 2026
@sadiksaifi
sadiksaifi deleted the fix/verify-macos-release-artifacts branch September 20, 2026 10:59
@sadiksaifi

Copy link
Copy Markdown
Owner Author

Superseded by #138 after renaming the branch to fix/verify-release-artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant